Rethinking Africa’s Approach to the Politics of AI Governance and Regulation

By Paul Kimumwe |

The past few years have witnessed a growing urgency for frameworks that regulate and harness the development and implementation of new and emerging technologies, especially Generative Artificial Intelligence (Gen AI).

At the international and regional level, the United Nations (UN) and the African Union (AU) have established norms through resolutions, strategies and guidelines to affirm the relationship between technology and human rights, and provide benchmarks for Member States developing rights-respecting AI governance and regulatory frameworks.

In March 2024, the UN adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that also benefit sustainable development. The resolution also calls upon Member States and other stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”

The 2024 resolution reaffirmed that “the same rights that people have offline must also be protected online, including throughout the life cycle of artificial intelligence systems.” It called upon member states to ensure that national AI governance and regulatory frameworks “promote safe, secure and trustworthy artificial intelligence systems” that are inclusive and benefit everyone in an equal manner.

In August 2025, the UN adopted resolution 79/325, establishing the Independent International Scientific Panel on AI and Global Dialogue on AI Governance. It aims to provide a platform to discuss international cooperation, share best practices and lessons learned, and to facilitate open, transparent and inclusive discussions on AI governance. However, a year earlier, in July 2024, the AU adopted the Continental AI Strategy, which emphasises the development of robust governance regimes for AI founded on ethical principles, democratic values, human rights, and the rule of law, in line with the AU  Agenda 2063.

Both the UN resolutions on AI and the AU continental strategy came on the backdrop of other AI-related policy guidelines such as Center for AI and Digital Policy’s 2018 Universal Guidelines for AI, the Organization for Economic Cooperation and Development (OECD) 2019 AI Principles / G20 AI Guidelines, the United Nations Education Scientific and Cultural Organization (UNESCO’s) 2021 Recommendation on the Ethics of AI, and the European Union Commission’s (EUC) 2024 European Union AI Act.

Many African countries have been actively developing AI-related laws, policies, and strategies. Rwanda was the first to adopt a national AI policy in 2019, followed by Ghana’s National Artificial Intelligence Strategy in October 2022, Egypt’s National Artificial Intelligence Strategy in January 2025, and Kenya’s own strategy in May 2025. Benin, Côte d’Ivoire, Ethiopia, Mauritius, Nigeria, Tunisia, Zambia, and Zimbabwe are among others that have developed AI policies or strategies. Others, such as Burkina Faso, Guinea, Lesotho, Mali, Namibia, and Uganda, are still at different stages in developing their AI policies or strategies.

A case of history repeating itself?

While all these have been welcome developments in the governance and regulation of AI, studies show that the adoption of international and regional human rights instruments and national laws, policies and strategies is often just the first step in a long process. If not well managed, it often results in provisions that are, although of a progressive nature, are hard to implement and fail to address local needs and realities.

This is because the process of drafting these laws and strategies in many developing contexts is often devoid of meaningful multistakeholder consultations and engagement. Moreover, there has also been a tendency to adopt and replicate models from the global North, whose texts, while progressive, have faced strong resistance from Member States as they sometimes do not align with local contexts and cultural norms.

For example, many African countries, including Algeria, Ethiopia, Cameroon, Kenya, Mauritius, Namibia, Rwanda, South Africa, and Uganda, expressed strong reservations about certain provisions contained in the Protocol to the African Charter on Human and People’s Rights on the Rights of Women in Africa (Maputo Protocol).

Additionally, most of these models are state-centric and grounded in frameworks that create a distinct binary between duty-bearers and rights-holders, but do not articulate how and what each party needs to do to ensure meaningful implementation of the initiatives.

While the state-centric and rights-based approaches may seem attractive, in practice, their relevance in advancing digital rights is often undermined, especially when the prescribed provisions and action points do not align with the country’s current social, economic and political realities. Indeed, cases abound in which initial promises have fizzled over time due to the political leadership’s inaction (and sometimes unwillingness) to fully adopt and implement the resolutions or strategies.

For example, it took almost nine years for the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) to enter into force on June 8, 2023, after its adoption in 2014. Indeed, more countries (40) have enacted data protection laws as compared to those that have ratified (16), highlighting a disconnect between national legal reforms and their commitment to continental frameworks. Similarly, the AU Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa, adopted on January 30, 2018, took six years to enter into force, after the 15th ratification was achieved.

More critically, however, the lack of political will often reflect in the absence of clearly defined funding mechanisms for the implementation of these policies and strategies. As a result, even well-designed and progressive frameworks face implementation challenges due to structural flaws and insufficient funding.

For example, while Africa has scored highly in enacting Data Protection laws, which have become central to ongoing AI governance frameworks, one issue affecting their effective implementation is the lack of clear funding mechanisms for the regulatory bodies responsible for oversight and implementation. Other challenges include weak governance structures that deny these oversight bodies financial, decisional and operational independence and place them under the supervision of political appointees rather than parliament.

Designing for Failure?

Apart from Kenya, most African countries that have developed or are in the process of developing an AI strategy or policy do not provide for budgetary allocations or estimates for the implementation of their AI strategies, laws or policies. Countries such as Rwanda provide for a project-level funding framework, while others, such as Egypt and Mauritius, rely on programmatic budgets to fund the implementation of their strategies.

Even then, while implementation of Kenya’s National Artificial Intelligence Strategy (2025–2030) was costed at KSh 152 billion over a period of five years, a review of Kenya’s 2026/27 national budget shows no dedicated funding allocation for the strategy. Instead, the Sh8.6 billion allocated to the ICT sector mainly targets the expansion of broadband access, the strengthening of digital skills, and the digitisation of government services.

Additionally, in countries such as Ethiopia and Rwanda, while the policies provide for the establishment of an implementation body, several functions have been split across different ministries, departments and agencies (MDAs), which, in practice, would pose a significant challenge to meaningful execution.

For example, Rwanda’s AI policy mandates the Responsible AI office under the Ministry of ICT and Innovation to be responsible for effective tech implementation. It also positions the Rwanda Utilities Regulatory Authority (RURA) as the technical regulator responsible for developing ethical AI guidelines and principles, and the National Cyber Security Authority (NCSA) to oversee data protection compliance relevant to AI systems.

In Ethiopia, the policy designates the Ethiopian Artificial Intelligence Institute (EAII) as the national coordinating body responsible for implementation, standards development, and capacity building, and the Ministry of Innovation and Technology is responsible for providing policy oversight. Other sectoral agencies, such as the Ethiopian Communications Authority (ECA), the Ministry of Health, and the National Bank, have mandates over telecommunications and data matters, health-sector-related AI, and financial AI, respectively.

While a multisectoral approach to policy and strategic implementation can improve cohesiveness and legitimacy, the approach is prone to risks such as divergent priorities, internal conflicts, power struggles, and regulatory fragmentation, which are likely to affect how the policies and strategies are executed.

Implications for the Future of AI Governance and Regulation

In many African countries, the development of AI governance and regulatory structures is still in its infancy and presents a unique opportunity for Africans to shape their own destiny on how AI should be developed and deployed in ways that respond to and respect local needs and contexts.

Enactment of AI-specific Laws

In many countries, governments are relying on existing laws, such as data protection, communications, and cyber-related legislation, alongside the AI policies and strategies being developed. Given the evolving nature of AI, countries need to work towards enacting AI-specific laws that clearly define and contextualise AI.

Empowering the Oversight Bodies

As currently structured, many of the existing and proposed oversight bodies are either not yet operational or lack a clear mandate and sufficient resources for effective oversight. Additionally, many of them are situated within fragmented regulatory environments with overlapping responsibilities, which results in uncoordinated implementation. It is important, therefore, that the mandate of the oversight bodies and resources are clearly defined and guaranteed to ensure independence and eliminate the possibility of political interference.

Meaningful Stakeholder Participation

Having empowered stakeholders who are meaningfully engaged and participate in the development processes for policies, laws and strategies is critical to ensuring that the resulting instruments address real needs, are people-centred and implementable, and have government buy-in, as reflected in the government’s funded priorities.

Adopting a Human Rights-Centred Approach

A 2025 study by CIPESA shows that in many countries, the adoption of a human rights-centred approach to AI governance remains aspirational due to gaps in implementation, technical capacity, and stakeholder engagement in policy development and implementation. It is important, therefore, that current efforts prioritise safeguarding fundamental human rights and freedoms, enhancing human capabilities over replacement, and ensuring meaningful human control, transparency, fairness, and inclusivity in AI systems.

How Applicable is the Multi-stakeholder Approach to Internet Governance in Africa?

By Ashnah Kalemera |
What is the value for Africans in international Internet Governance processes if the approach towards Internet governance on the continent has not fully embraced the multi-stakeholder model? This was among the concerns heard during debates at the 11th Internet Governance Forum (IGF), as some participants questioned the applicability of the global internet governance agenda to Africa.
At a global level, the IGF, an initiative of the United Nations, discusses public policy issues related to the internet. The annual gathering drives best practices and common understanding of how to maximise internet opportunities and address the risks and challenges it faces. At the core of the IGF is the multi-stakeholder approach which aims to bring together individuals, groups or organisations with a stake in the internet to cooperate in advancing policy and practice for its development globally.
This approach is said to be “optimal” in ensuring government, business, civil society and the technical community take part in making policy decisions for the internet that are accountable, sustainable and effective.

Why the multi-stakeholder approach?

  • Decisions impact a wide and distributed range of people and interests,
  • There are overlapping rights and responsibilities across sectors and borders,
  • Different forms of expertise are needed, such as technical expertise, and
  • Legitimacy and acceptance of decisions directly impact implementation.

Internet Governance: Why the Multi-stakeholder Approach Works (Internet Society)

National and regional IGF initiatives (NRI) are similarly conducted to address community needs and involve multiple stakeholders. However, few African stakeholders participate at the global IGF and NRIs, rendering the principles of multi-stakeholderism difficult to achieve.

More than 2,000 participants from 123 countries attended the 2016 IGF held in Mexico. By stakeholder group, civil society constituted the majority (44.5%). Government representation was 20.5% and private sector was 15.5%. By region, Africa had the second lowest regional representation– 6.7%, beating only Eastern Europe from which 2.5% of participants originated.

There are up to 16 national, sub-regional and regional IGFs in Africa. Of the African countries that hosted forums during 2016, most were civil society led with some support from government reported – for instance in Ghana, Nigeria and Uganda. However, there was limited participation by the judiciary and law enforcement, youth and the private sector.
Organisers of the Africa Internet Governance Forum (AIGF) and national forums say there is a challenge of multi-stakeholder participation at gatherings on the continent due to lack of political will and limited knowledge and awareness of internet governance issues, among other reasons.
Organisers of the regional AIGF also reported limited representation by policy makers and other government officials. Private sector and youth were reportedly underrepresented at the fifth AIGF held in Durban, South Africa, last October.
According to Olusegun Olugbile who sits on the technical committee of the AIGF and the Nigeria national forum, limited stakeholder participation in national and regional internet governance forums was due to a lack of trust and confidence in the dialogue and ensuing outcomes.
Speaking at the African Union (AU) session at the IGF, Olugbile stated that bringing more stakeholders to the table on internet governance in Africa requires “embracing” policy documents from the continent, such as the African Union Convention on Cyber Security and the African Declaration on Internet Rights –  less so international instruments – so as to ensure contextual understanding of key concerns. This would contribute to a demonstration of value in participation for the stakeholders currently not participating. Furthermore, it would ensure that agendas for debate are localised to suit African needs and follow ups on recommendations are directly linked to the mandate of the relevant stakeholders.
Whereas discussants at the Africa themed sessions also called for more public-private partnership efforts in pursuing the principles of internet governance in Africa, regional bodies such as the AU were also called upon not only to convey outcomes to governments but to actively advocate and “push” for the implementation of recommendations from the AIGF among member states.
Meanwhile, the Africa School of Internet Governance (AfriSIG), which started in 2013 was commended for its role in bridging the internet governance knowledge and skills gap on the continent. To-date, the school has graduated over 150 individuals from government, the private sector and civil society across Africa in the principles and procedures of internet governance. Continued capacity building efforts by the school and other practitioners were recommended.
The 2016 IGF was convened under the theme ‘Enabling Inclusive and Sustainable Growth” from December 6–9, 2016 in Jalisco, Mexico.
 
 

Civil Society’s Proposals on The African Cybersecurity Convention

In December 2013, the Kenya ICT Action Network (KICTANet) led online discussions on the proposed African Union Convention on Cyber Security (AUCC). The convention establishes a framework for cyber security in Africa “through organisation of electronic transactions, protection of personal data, promotion of cyber security, e-governance and combating cybercrime.”
Civil society and academia have raised concerns about some of the articles in the convention, which had earlier been expected to be signed in January 2014. Latest reports indicate that, at the earliest, the law could be signed in June this year.
The report on the discussions will be used by KICTANet and partners such as CIPESA to create awareness and lobby African governments to pass legislation and instruments that fully support the privacy of individuals and the fully enjoyment of their freedom of expression online.
The stated background to the convention is that the African Union is seeking ways to intensify the fight against cybercrime across the continent“in light of the increase in cybercrime, and the lack of mastery of security risks by African countries.”
Furthermore, the AU states that a major challenge for African countries is the lack of adequate technological security to prevent and effectively control technological and informational risks. As such, it adds, “African States are in dire need of innovative criminal policy strategies that embody States, societal and technical responses to create a credible legal climate for cyber security”.
The intentions may be legitimate but, as noted by the online discussions, some of the articles in the current version of the convention could be used to negate individuals’ privacy and their right to express themselves through online mediums.
Take, for example, Article III – 34. It states that AU member states have to “take necessary legislative or regulatory measures to set up as a penal offense the fact of creating, downloading, disseminating or circulating in whatsoever form, written matters, messages, photographs, drawings or any other presentation of ideas or theories of racist or xenophobic nature using an a computer system.”
How does this clause balance with the fundamental right to freedom of expression? Experts argue that this clause is problematic as it requires a measure of truth, which is hard to actually legislate or determine owing to the relativity of truth. They add that this sort of law would likely be unenforceable.
The discussion noted that although African countries needed legal framework on cybercrime, the current proposals need numerous amendments. The discussions also noted a need for the African Union Commission to engage with civil society to draw up progressive and enforceable laws. However, civil society had the added task of creating awareness and capacity among citizens on cyber security and the need to uphold freedoms of expression online.
These discussions were conducted on multiple lists of KICTANet and the Internet Society (ISOC) Kenya and on the I-Network and ISOC Uganda ists moderated  by the Collaboration on International ICT Policy in East and Southern Africa (CIPESA), from 25 – 29, November 2013. They were also shared through numerous pan-Africa and global lists on ICT policy and online freedom.
Download the full discussions report here.